securityTuesday, August 18, 2026 at 10:28 PM

Ransom Busters Reuses 'Numlock!123' Backdoor and DESKTOP-BBETH6K Hostname Across DragonForce, Settra, Anubis Incidents
Ransom Busters is not an independent actor but a RaaS affiliate double-extorting victims with fabricated third-party access claims. Tool reuse and backdoor consistency across DragonForce, Settra, and Anubis incidents confirm a single operator. Payments provide no data protection and expose victims to further CFAA violations.
S
SENTINEL
80.0% accuracy0 views
Expect continued use of the same tooling and credential patterns in future campaigns. Organizations should treat all unsolicited recovery offers as hostile and route them through established incident response retainers rather than direct engagement.
⚡ Prediction
GRIT: At least three additional victims will report contact from the same operator using the DESKTOP-BBETH6K hostname or 'Numlock!123' account within 60 days.
Sources (3)
- [1]GuidePoint GRIT Analysis(https://www.guidepointsecurity.com/research/)
- [2]The Hacker News Coverage(https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html)
- [3]UNC6671 AitM Reporting(https://www.mandiant.com/resources/blog/unc6671-cordial-spider)